First published: Fri Apr 08 2022(Updated: )
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >=5.17<5.17.1 | |
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux | =7.0 | |
Fedora | =35 | |
netapp active iq unified manager vsphere | ||
netapp solidfire\, enterprise sds \& hci storage node | ||
netapp solidfire \& hci management node | ||
netapp hci compute node firmware | ||
netapp hci compute node | ||
netapp h300s firmware | ||
netapp h300s | ||
NetApp H500S Firmware | ||
netapp h500s | ||
netapp h700s firmware | ||
netapp h700s | ||
netapp h300e firmware | ||
netapp h300e | ||
netapp h500e firmware | ||
netapp h500e | ||
netapp h700e firmware | ||
netapp h700e | ||
netapp h410s firmware | ||
netapp h410s | ||
netapp h410c firmware | ||
netapp h410c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28796 is a vulnerability in the Linux kernel before version 5.17.1 that allows a use-after-free caused by a transaction_t race condition in the jbd2_journal_wait_updates function in fs/jbd2/transaction.c.
CVE-2022-28796 is considered high severity with a CVSS score of 7.
The Linux kernel versions before 5.17.1, Redhat Enterprise Linux versions 6.0 and 7.0, and Fedoraproject Fedora version 35 are affected by CVE-2022-28796.
To fix CVE-2022-28796, it is recommended to update to the Linux kernel version 5.17.1 or later.
You can find more information about CVE-2022-28796 in the following references: [Link 1](https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.1), [Link 2](https://github.com/torvalds/linux/commit/cc16eecae687912238ee6efbff71ad31e2bc414e), [Link 3](https://security.netapp.com/advisory/ntap-20220506-0006/).